CVE-2026-1213

All versions of askbot before and including 0.12.2 allow an attacker authenticated with normal user permissions to modify the profile picture of other application users.This issue affects askbot: 0.12.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:askbot:askbot:*:*:*:*:*:*:*:*

History

14 Apr 2026, 14:58

Type Values Removed Values Added
CPE cpe:2.3:a:askbot:askbot:*:*:*:*:*:*:*:*
First Time Askbot askbot
Askbot
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
Summary
  • (es) Todas las versiones de askbot anteriores e incluyendo la 0.12.2 permiten a un atacante autenticado con permisos de usuario normal modificar la imagen de perfil de otros usuarios de la aplicación. Este problema afecta a askbot: 0.12.2.
References () https://askbot.com/ - () https://askbot.com/ - Product
References () https://fluidattacks.com/advisories/ghost - () https://fluidattacks.com/advisories/ghost - Exploit, Third Party Advisory
References () https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d - () https://github.com/ASKBOT/askbot-devel/commit/3da3d75f35204aa71633c7a315327ba39cb6295d - Patch

27 Jan 2026, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 14:15

Updated : 2026-04-14 14:58


NVD link : CVE-2026-1213

Mitre link : CVE-2026-1213

CVE.ORG link : CVE-2026-1213


JSON object : View

Products Affected

askbot

  • askbot
CWE
CWE-639

Authorization Bypass Through User-Controlled Key